CVE-2026-75439
nicheNULL Pointer Dereference DoS in Free5GC 4.2.2 UPF Component
Free5GC version 4.2.2 contains a NULL pointer dereference (CWE-476) in its User Plane Function (UPF) component, the part of the open-source 5G core that carries subscriber data traffic. A remote, unauthenticated attacker can trigger the flaw by sending a specially crafted request to the UPF, most plausibly a malformed packet on its control interface, causing the process to crash and denying service to any users whose traffic transits that UPF. The impact is limited to availability — confidentiality and integrity are unaffected, consistent with the CVSS 7.5 score (network vector, low complexity, no privileges or user interaction required). Affected parties are operators, universities, and researchers running Free5GC 4.2.2, typically in lab or testbed environments rather than commercial networks. No public proof of concept is known, the flaw is not in the CISA KEV catalog, and EPSS places it at only 0.2% likelihood of exploitation in the next 30 days.
What to do: Upgrade to a Free5GC release newer than 4.2.2 once upstream publishes a fix, or apply the upstream patch to the UPF component directly. Restrict network reachability to the UPF's service and PFCP ports so only trusted SMF/gNodeB addresses can connect, and monitor the UPF process for unexpected crashes or rapid restarts as an indicator of malformed-message attempts.
| Free5GC (UPF component) | 4.2.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component
- Weakness
- CWE-476
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.